Remove the push-to-main trigger from .github/workflows/deploy.yaml so merges
no longer deploy automatically; deploys now run only via the Actions "Run
workflow" button (workflow_dispatch). No job content, permissions, or
reusable-workflow inputs changed. README and the auth deploy runbook updated
to match.
First-time deploy procedure for the Phase 2a Cognito auth substrate: the five
one-time prerequisites (CDK bootstrap, the two Google secrets with exact JSON
shapes, the githubdeploy-sh-mcp OIDC role, the managed Google Groups), the
synth → diff → watched manual first deploy → CD hand-off flow, post-deploy
validation (ESSENTIALS + V2 trigger, finance client ceiling, group-sync run,
deny-list hard-revocation smoke test), and rollback/teardown (RETAIN tables;
0a spike teardown deferred until sh-mcp-auth is validated).
Notes that CD (deploy.yaml) is already wired and red on every merge until the
OIDC deploy role exists, and that no Cognito hosted-UI domain ships in 2a
(OAuth code flow deferred to 2b surface wiring).